andreas-kurtz.de
http://www.andreas-kurtz.de/advisories/AKADV2008-001-v1.0.txt CVE-2008-6511
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
Record summary
CVE-2008-6511 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit.
Description
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site ScriptingExploitDB exploitby Andreas KurtzNot analyzed1 file
References
420081108 [AK-ADV2008-001] Openfire Jabber-Server: Multiple Vulnerabilities (Authentication Bypass, SQL injection, ...)mailing list
http://www.securityfocus.com/archive/1/498162/100/0/threaded nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-6511 7075exploit
https://www.exploit-db.com/exploits/7075